3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1112
Drag and Drop Multiple File Upload Contact Form 7 Web Windows
4.7
MEDIUM
EPSS
31.8%
2023 CWE-23 1 PoC

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.

CVE-2023-1442
QYKCMS Web
4.7
MEDIUM
EPSS
0.5%
2023 CWE-434 1 PoC

A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_system/api.php of the component Update Handler. The manipulation of the argument downurl leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223287.

CVE-2023-2307
builderio/qwik Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.

CVE-2023-0532
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219601 was assigned to this vulnerability.

CVE-2023-7178
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in Campcodes Online College Library System 1.0. This issue affects some unknown processing of the file /admin/book_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249365 was assigned to this vulnerability.

CVE-2023-1909
BP Monitoring Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225318 is the identifier assigned to this vulnerability.

CVE-2023-7236
Backup Bolt Web Windows
4.7
MEDIUM
EPSS
0.4%
2023 1 PoC

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.

CVE-2023-1759
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-1754
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-2369
Faculty Evaluation System Web Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/manage_restriction.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227645 was assigned to this vulnerability.

CVE-2023-0529
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-219598 is the identifier assigned to this vulnerability.

CVE-2023-0313
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-0531
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/booking_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219600.

CVE-2023-1879
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-0533
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this issue is some unknown functionality of the file admin/expense_report.php. The manipulation of the argument from_date leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-219602 is the identifier assigned to this vulnerability.

CVE-2023-1884
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-6302
CSZCMS Web
4.7
MEDIUM
EPSS
0.0%
2023 CWE-275 1 PoC

A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-29204
xwiki-platform Web ⚡ nuclei
4.7
MEDIUM
EPSS
1.0%
2023 CWE-601 0 PoCs

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as `http:/mydomain.com`. The problem has been patched on XWiki 13.10.10, 14.4.4 and 14.8RC1.

CVE-2023-7175
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability was found in Campcodes Online College Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/borrow_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249362 is the identifier assigned to this vulnerability.

CVE-2023-2947
openemr/openemr Web
4.7
MEDIUM
EPSS
22.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.